Privacy notice
Last updated 2 October 2026
This notice explains what personal data AddToThese collects, why, how long we keep it and what rights you have. AddToThese is operated by Nordic Byte LTD, a company registered in England and Wales (company number 16978110), registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. Nordic Byte LTD is the data controller. Contact: info@nordicbyte.co.uk.
What we collect
| Data | Why | Lawful basis |
|---|---|---|
| Email address, name, password hash (Argon2id) | To create and secure your account and send service email such as password resets | Contract |
| Google or GitHub account ID and verified email, if you sign in with them | To log you in | Contract |
| Two-factor secret and hashed recovery codes, if you turn on 2FA | To protect your account | Contract |
| Activity log: sign-ins and account changes, with IP address and browser user agent | Security and abuse investigation, shown to you on the Security page | Legitimate interests |
| Team membership: if you join a team, its owner sees your name and email address; if you invite someone, we store their email for 7 days to send the invitation | To run the Team plan | Contract; legitimate interests for invitees |
| Endpoints, custom domains, API token names and last-use times | To run the service you configured | Contract |
| Usage counters: bytes transferred and request counts per month | To apply plan limits and show your usage | Contract |
| Stripe customer and subscription IDs and status | To bill paid plans | Contract; legal obligation for accounting records |
| Session cookie and CSRF cookie | To keep you logged in and protect forms. Both are strictly necessary; we use no analytics or advertising cookies | Legitimate interests |
| Emails of visitors to URLs protected with email codes, and the one-time codes sent to them | To let in only the people the URL owner allowed. We process these on behalf of the URL owner, who decides who is allowed. | Legitimate interests (URL owner's security); codes are deleted within a day |
Traffic through your tunnels
Requests to your public URLs pass through our servers to your machine. We do not store request or response bodies. Our proxy and web server keep short-lived technical logs (time, host, path, status, client IP) for operating the service and handling abuse reports. You are responsible for any personal data your own service handles.
Who we share it with
We do not sell personal data. We use these processors:
- Stripe for payments. Card details go straight to Stripe and never reach our servers.
- Bunny.net (BunnyWay d.o.o., Slovenia) for DNS and the content delivery network in front of this website.
- Our hosting provider for the server that runs AddToThese, located in the European Economic Area.
- Google and GitHub, only if you choose to sign in with them.
- Let's Encrypt, which records the domain names we request certificates for, including your custom domains.
Where data leaves the UK or EEA (for example to Stripe or GitHub in the United States), the transfer relies on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses offered by those providers.
How long we keep it
- Account data: while your account exists. After you ask us to delete it, within 30 days, apart from what the next points require.
- Activity log entries: 12 months, then deleted automatically.
- Expired sessions and password reset links: deleted automatically.
- Billing records: 6 years, as UK accounting law requires.
- Database backups: 30 days on a rolling basis.
Your rights
Under UK GDPR, and EU GDPR where it applies to you, you can ask for a copy of your data, ask us to correct or delete it, object to or restrict processing based on legitimate interests, and ask for your data in a portable format. Write to info@nordicbyte.co.uk from the email address on your account and we will reply within one month. If you are unhappy with our answer you can complain to the UK Information Commissioner's Office at ico.org.uk, or to the data protection authority where you live.
Security
Passwords are hashed with Argon2id, API tokens are stored hashed, all traffic to our site uses HTTPS, and two-factor authentication is available on every plan.
Changes
If we change this notice in a way that matters, we will email account holders before the change takes effect.